How to Get User Login History

Microsoft Active Directory stores user logon history data in event logs on domain controllers. Starting from Windows Server 2008 and up to Windows Server 2016, the event ID for a user logon event is 4624. These events contain data about the user, time, computer and type of user logon. Using the PowerShell script provided above, you can get a user login history report without having to manually crawl through the event logs.
This is a part of the following how-to: https://www.netwrix.com/how_to_get_user_login_history.html

Source Code

This script has not been checked by Spiceworks. Please understand the risks before using it.